First published: Mon May 20 2024(Updated: )
A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/gnome-remote-desktop | <46.2-1~ubuntu24.04.2 | 46.2-1~ubuntu24.04.2 |
ubuntu/gnome-remote-desktop | <46.2 | 46.2 |
debian/gnome-remote-desktop | 0.1.7-1 0.1.9-5 43.3-1 44.2-8 | |
redhat/gnome-remote-desktop | <46.2 | 46.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.